RMIT University
Browse

ID2S password-authenticated key exchange protocols

journal contribution
posted on 2024-11-02, 02:33 authored by Xun YiXun Yi, Fang-Yu Rao, Zahir TariZahir Tari, Feng Hao, Elisa Bertino, Ibrahim KhalilIbrahim Khalil, Albert Zomaya
In a two-server password-authenticated key exchange (PAKE) protocol, a client splits its password and stores two shares of its password in the two servers, respectively, and the two servers then cooperate to authenticate the client without knowing the password of the client. In case one server is compromised by an adversary, the password of the client is required to remain secure. In this paper, we present two compilers that transform any two-party PAKE protocol to a two-server PAKE protocol on the basis of the identity-based cryptography, called ID2S PAKE protocol. By the compilers, we can construct ID2S PAKE protocols which achieve implicit authentication. As long as the underlying two-party PAKE protocol and identity-based encryption or signature scheme have provable security without random oracles, the ID2S PAKE protocols constructed by the compilers can be proven to be secure without random oracles. Compared with the Katz et al.'s two-server PAKE protocol with provable security without random oracles, our ID2S PAKE protocol can save from 22 to 66 percent of computation in each server.

History

Journal

IEEE Transactions on Computers

Volume

65

Number

7450662

Issue

12

Start page

3687

End page

3701

Total pages

15

Publisher

IEEE

Place published

United States

Language

English

Copyright

© 2016 IEEE

Former Identifier

2006069427

Esploro creation date

2020-06-22

Fedora creation date

2017-01-11

Usage metrics

    Scholarly Works

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC